Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg4r-vvqm-988m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

EPSS

Процентиль: 67%
0.00544
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
nvd
около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

CVSS3: 7.1
debian
около 5 лет назад

Path traversal vulnerability in package upload functionality in GitLab ...

EPSS

Процентиль: 67%
0.00544
Низкий

Дефекты

CWE-22